首页    期刊浏览 2024年09月20日 星期五
登录注册

文章基本信息

  • 标题:Behaviour Based Worm Detection and Signature Automation
  • 本地全文:下载
  • 作者:Anbar, Mohammed ; Manickam, Selvakumar ; Hosam, Al-Samarraie
  • 期刊名称:Journal of Computer Science
  • 印刷版ISSN:1549-3636
  • 出版年度:2011
  • 卷号:7
  • 期号:11
  • 页码:1724-1728
  • DOI:10.3844/jcssp.2011.1724.1728
  • 出版社:Science Publications
  • 摘要:Problem statement: A worm is a malicious piece of code that self-propagates, often via network connections, to exploit security flaws in computers connected through the network. In general, worms do not need any human intervention to propagate and are considered a real threat to network assets and the properties of organizations. An Intrusion Detection Systems (IDSs) are employed to detect the presence of the worms in the network. Approach: This study proposed a new behaviourbased worm detection and signature automation approach that consists of scanning characteristics to find vulnerable hosts and indicate the correlation between an infected host and potential destination hosts. Results: This approach can be distinguish between network scanning (random and sequential TCP and UDP worm scanning) triggered by infected and non-infected hosts. In addition, the ability to detect the worms based on its behaviours. Conclusion: Identifying network worms at an early stage can increase the protection of network services and vulnerable hosts.
  • 关键词:Network scanning; worm detection; Intrusion Detection Systems (IDSs); Artificial Neural Networks (ANNs); Destination-Source Correlation (DSC)
国家哲学社会科学文献中心版权所有